2024 CVE Vulnerabilities

39,256 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-38487HIGH7api-gateway container running with root privilege would allow an attacker to escape the container and access host system...
CVE-2024-30476MEDIUM5.4PowerStore contains a Stored Cross-Site Scripting Vulnerability in the PowerStore Manager. A remote authenticated low-pr...
CVE-2024-24909HIGH8.8Dell OpenManage Integration with Microsoft Windows Admin Center contains a Remote Code Execution vulnerability in the ga...
CVE-2024-22451MEDIUM6.7Dell Peripheral Manager, versions from 1.5.1 to 1.7.2, contain an uncontrolled search path element vulnerability. An att...
CVE-2024-22447HIGH7.8Dell Peripheral Manager, versions prior to 1.7.3, contain an uncontrolled search path element vulnerability. An attacker...
CVE-2024-45636MEDIUM4.4IBM Security QRadar EDR 3.12 through 3.12.24 stores user credentials in plain text which can be read by a local privileg...
CVE-2024-32110MEDIUM4.3Cross-Site request forgery (CSRF) vulnerability in Magepeople inc. WpEvently allows Cross Site Request Forgery. This is...
CVE-2024-21944MEDIUM5.3Improper input validation for DIMM serial presence detect (SPD) metadata could allow an attacker with physical access, r...
CVE-2024-58350MEDIUM4Ghidra before 11.2 contains a use after free vulnerability in the Sleigh backend caused by undefined static initializati...
CVE-2024-56123——Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
CVE-2024-56122——Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
CVE-2024-56121——Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
CVE-2024-56120——Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
CVE-2024-58349CRITICAL9.8WordPress Theme Travelscape 1.0.3 contains an arbitrary file upload vulnerability that allows unauthenticated attackers ...
CVE-2024-58348CRITICAL9.8WordPress Background Image Cropper version 1.2 contains a remote code execution vulnerability that allows unauthenticate...
CVE-2024-27892CRITICAL9.6Affected platforms running Arista EOS with OpenConfig configured, a gNMI Set request can be run when it should have been...
CVE-2024-27891MEDIUM6.9On affected platforms running Arista EOS with MACsec and egress ACLs configured on the same interfaces, the ACL policies...
CVE-2024-27890CRITICAL9.6Affected platforms running Arista EOS with OpenConfig configured, a gNMI Set request can be run when it should have been...
CVE-2024-6858MEDIUM6.5In Arista’s EOS when in 802.1X mode, multi-auth unauthenticated hosts might be allowed access to a switch port if there ...
CVE-2024-47273MEDIUM4.3An improper limitation of a pathname to a restricted directory ('Path Traversal') vulnerability in Backup Task functiona...
CVE-2024-47263MEDIUM4.1An improper limitation of a pathname to a restricted directory ('Path Traversal') vulnerability in Backup.Repository web...
CVE-2024-14036HIGH8.7Dräger Core 1.0.5 and Dräger M540 Converter Service 1.0.9 contain a denial of service vulnerability that allows network-...
CVE-2024-42206LOW3.1HCL iReflection Third party vulnerable and outdated components issue was detected in the web application
CVE-2024-52011HIGH8.3launch-editor allows users to open files with line numbers in editor from Node.js. Prior to version 2.9.0, due to the in...
CVE-2024-40646HIGH8.6Vertex is a management tool for PT (Private Tracker) users to manage streaming and watching videos. Versions prior to co...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now